Web Hosting Forum | Lunarpages
News: Server Migrations to San Diego: Deneb, Felix and Tsohea are moving to San Diego starting Tuesday, December 30, 2008 at 10pm Pacific. They will complete their moves Friday night, January 2, 2009

Isis, Seth and Ez-web-n-mail will move physically on Friday, January 2, 2009

Please see the forum posts at http://www.lunarforums.com/lunarpages_web_hosting_server_information-b54.0/

+ Submit Your Own Web Site for the January 2009 Site of the Month Contest!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
January 07, 2009, 07:02:55 PM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: Latest server scans for outdated scripts.  (Read 24385 times)
Stephanie®
Administrator
Master Jedi
*****
Offline Offline

Posts: 1096



« on: April 17, 2008, 03:11:52 AM »

Hi,

We will be scanning our servers for the following installations and advising customers to check for regular updates:


joomla 1.5.8 reported
Advisory
http://www.securityfocus.com/archive/1/499295
Vendor
http://www.joomla.org/
Please note joomla do not appear to have acknowledged this to date, however we are giving a heads up


phpList < 2.10.8
Advisory
http://secunia.com/Advisories/33186/
Vendor


xoops < 2.3.2b
Advisory
http://www.securityfocus.com/bid/32685
Vendor
http://xoops.org/


MyBB < 1.4.4
Advisory
http://www.securityfocus.com/bid/32467
Vendor
http://mybboard.net
Patch info
http://community.mybboard.net/thread-41036.html


Joomla Image Browser 0.1.5
Advisory
http://www.securityfocus.com/bid/31458
Patch info
An update is now available from the vendor


Invision Power Board <= 2.3.5
Advisory
http://www.securityfocus.com/archive/1/495841
Vendor
http://invisionpower.com
Patch info
http://forums.invisionpower.com/index.php?showtopic=276512

4images gallery all versions lower than 1.7.3 (1.7.6 is the latest)

Advisory
http://secunia.com/advisories/22349/

Vendor
http://www.4homepages.de/4images/download.php


Postnuke all versions lower than 0.7.6.4

Vendor
http://community.postnuke.com/index.php?name=News&file=article&sid=2787

Advisory
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1591
http://secunia.com/advisories/22983/
http://secunia.com/advisories/23849/ less critical, no update for this as of yet.



Joomla all versions lower than 1.5.7

Vendor
http://joomlacode.org/gf/project/joomla/frs/?action=FrsReleaseView&release_id=6828

Advisory
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1733
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1559
http://www.securityfocus.com/bid/28900/info


mambo all versions lower than 4.6.3

Vendor
http://sourceforge.net/projects/mambo/

Advisory
http://secunia.com/advisories/28670/



wordpress all versions lower than 2.6.5

Vendor
http://wordpress.org/download/

Advisory
http://www.securityfocus.com/archive/1/498652/30/0/threaded (XSS vulnerability in RSS Feed Generator)
http://www.securityfocus.com/bid/28935
http://secunia.com/advisories/28823/
http://xiam.menteslibres.org/pages/advisories/wordpress-2-5-salt-cracking-vulnerability
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1646
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1304


vBulletin
Vendor
http://www.vbulletin.com/

Vulnerable Packages
vBulletin 3.7.2 Patch Level 1.
vBulletin 3.6.10 Patch Level 3.
Older versions are probably affected too, but they were not checked.

Advisory
http://www.securityfocus.com/archive/107/308433

updates and patch info
http://www.vbulletin.com/forum/showthread.php?t=282133


You may already have patched your scripts or updated to a non vulnerable version, the scanner will pick out everything less than the latest up to date version and may also pick up current versions in the case where a patch may be required.
I apologize in advance if you receive an erroneous email and thank you for taking care of your account and ensuring your scripts are up to date.
If the tagging is incorrect and persistant, please be sure to contact support@lunarpages.com and our staff will be happy to help.

The initial scans will email an advisory notice only, please understand that these measures are for the security of your account and server helping to prevent unwanted file inclusions and hacks, whilst ensuring the stability of all accounts.


Thank you in advance for your patience and understanding.
« Last Edit: December 17, 2008, 07:19:03 AM by Stephanie® » Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.6 | SMF © 2006-2008, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM